Is io.jenkins.plugins:atlassian-bitbucket-server-integrationsafe?
3 known vulnerabilities, worst severity HIGH.
cvss
8.8
how bad it is if exploited, out of 10
epss
0.30%
chance of exploitation in the next 30 days
xyz score
3.3
CyberXYZ composite, out of 10
fig. 01 — GHSA-qjw6-xvrm-5f2h, the advisory selected below
// advisories
GHSA-qjw6-xvrm-5f2h
HIGHCVE-2025-24398
An extension point in Jenkins allows selectively disabling cross-site request forgery (CSRF) protection for specific URLs. Bitbucket Server Integration Plugin implements this extension point to support OAuth 1.0 authentication.